CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A large pharmaceutical company is developing a new drug. The project involves significant regulatory compliance requirements (e.g., FDA regulations) and complex clinical trials. To manage the risk of non-compliance, the company establishes a dedicated regulatory affairs department responsible for interpreting regulations, developing compliance procedures, and conducting internal audits. This department's ongoing activities are an example of which type of control?
- ACompensating control
- BPreventive control
- CCorrective control
- DDetective control
Show answer & explanationAnswer & explanation
Correct answer: B. Preventive control
The dedicated regulatory affairs department's activities, such as interpreting regulations and developing compliance procedures, are designed to ensure that non-compliance does not occur in the first place. These actions proactively prevent breaches of regulations, characterizing them as preventive controls.
Why the other options are wrong
- A. Compensating controls are alternative controls that achieve the same objective as a primary control when the primary control cannot be fully implemented.
- C. Corrective controls fix problems AFTER they have been detected.
- D. Detective controls identify incidents AFTER they have occurred.
Preventive Control
A preventive control is designed to stop an undesirable event from occurring by proactively addressing the root causes or conditions that lead to the risk.
- Acts before an event takes place.
- Aims to reduce likelihood of risk.
- Examples include segregation of duties, access controls, policies, and training.
Memory trick: Prevent before, Detect during, Correct after.